AI Act for companies that use AI
Most AI Act obligations fall on those who build AI. A company that only uses AI (the deployer) still has obligations of its own — and some already apply. Here is an overview by date and the tools that help you find your way.
What applies and from when
- 2 Feb 2025
AI literacy and prohibited practices
Companies take measures to support the AI literacy of the people operating and using AI systems on their behalf. Regulation (EU) 2026/1744 reworded the duty: no specific level of literacy of any individual has to be guaranteed. Prohibited practices must not be used — the one closest to an ordinary company is inferring employees' emotions in the workplace, unless for medical or safety reasons.
Art. 4(1) of Regulation (EU) 2024/1689 · Art. 5(1)(f) of Regulation (EU) 2024/1689 · Art. 113(3)(a) of Regulation (EU) 2024/1689
- 2 Aug 2026
Transparency
A deployer of emotion recognition or biometric categorisation informs the persons exposed. Deep fakes and text published to inform the public on matters of public interest are disclosed as artificially generated (not required for text that underwent editorial review with editorial responsibility). Telling people they are talking to an AI chatbot is the provider's duty — check it with your vendor.
Art. 50(1) of Regulation (EU) 2024/1689 · Art. 50(3) of Regulation (EU) 2024/1689 · Art. 50(4) of Regulation (EU) 2024/1689 · Art. 113(2) of Regulation (EU) 2024/1689
- 2 Dec 2026
New prohibitions and output marking
The prohibitions added by Regulation (EU) 2026/1744 apply: intimate imagery of an identifiable person without their explicit consent and child sexual abuse material. Providers of generative systems placed on the market before 2 Aug 2026 must mark outputs in a machine-readable format by this date.
Art. 5(1)(ba) of Regulation (EU) 2024/1689 · Art. 5(1)(bb) of Regulation (EU) 2024/1689 · Art. 111(4) of Regulation (EU) 2024/1689
- 2 Dec 2027
High-risk systems (Annex III)
If you use AI for example in recruitment or to assess the creditworthiness of natural persons, the deployer obligations apply from this date: use the system per its instructions, human oversight, monitoring and log retention. The date was set by Regulation (EU) 2026/1744.
Art. 6(2) of Regulation (EU) 2024/1689 · Art. 26(1) of Regulation (EU) 2024/1689 · Art. 113(3)(c) of Regulation (EU) 2024/1689
How NISMap helps
Tools that exist in NISMap today. Results are indicative, not legal advice.
AI system inventory
A record of the AI systems your company uses or builds: purpose, vendor, role and what the system does with people and data. A system can be linked to the asset register.
OpenRisk classification
An indicative category for each system — prohibited practice, high-risk, transparency or minimal risk — with article citations and the date each obligation applies from.
OpenAI literacy
A record of measures supporting AI literacy (training, e-learning, guidance, rules of use) and a checklist based on what the Regulation actually requires.
OpenTransparency
A decision tree and notice templates for a chatbot, synthetic text and deep fakes.
OpenAI Act quick assessment
6 areas, 18 questions with references to the articles of the Regulation, no signup.
OpenSlovak and Czech AI Act laws
The Regulation applies directly. The laws designating supervisory authorities and penalties have not yet been adopted in Slovakia or the Czech Republic — the drafts are in the legislative process. NISMap therefore cites no national provision. We follow the developments in the regulatory feed.
Regulatory feedClassification in an AI assistant (MCP)
The public NISMap MCP server offers the same classification as the ai_act_classify tool. An assistant that supports MCP passes the system's properties and gets the category, obligations with citations and dates of application. No signup and no API key.
claude mcp add --transport http nismap https://nismap.com/api/mcpMCP server documentationFrequently asked questions
Does the AI Act apply to a company that only uses AI?
Yes. Whoever uses an AI system under its authority (outside personal non-professional activity) is a deployer under Art. 3 of Regulation (EU) 2024/1689. It has obligations of its own: literacy under Art. 4(1) of Regulation (EU) 2024/1689, prohibitions under Art. 5(1) of Regulation (EU) 2024/1689, transparency under Art. 50(3) of Regulation (EU) 2024/1689 and Art. 50(4) of Regulation (EU) 2024/1689, and for high-risk systems the obligations under Art. 26(1) of Regulation (EU) 2024/1689 and the following paragraphs.
Do employees need an AI literacy certificate?
No. Art. 4(1) of Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 requires measures supporting literacy, taking into account people's knowledge, the context of use and the persons affected. No specific level of literacy of any individual has to be guaranteed.
We have a chatbot on our website. What do we have to do?
Under Art. 50(1) of Regulation (EU) 2024/1689 the provider must design the chatbot so that people know they are interacting with an AI system (unless obvious). Check it with your vendor; if you build the chatbot yourself, the duty is yours. It applies from 2 Aug 2026.
When do the obligations for high-risk systems apply?
For Annex III systems from 2 Dec 2027 under Art. 113(3)(c) of Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. An Annex III system is not high-risk if it meets one of the conditions of Art. 6(3) of Regulation (EU) 2024/1689 — except where it profiles natural persons, which is always high-risk.
Find out which obligations apply to you
Record your AI systems in the inventory and get an indicative classification with citations and dates for each.
Start an AI system inventoryIndicative overview under Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, not legal advice. Slovak and Czech national AI Act laws are not taken into account. For a binding assessment, consult a legal adviser.